• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

stacklok / toolhive / 30826608202 / 1
70%
main: 70%

Build:
DEFAULT BRANCH: main
Ran 03 Aug 2026 03:21PM UTC
Files 867
Run time 41s
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

03 Aug 2026 03:15PM UTC coverage: 69.924% (+0.06%) from 69.865%
30826608202.1

push

github

web-flow
Re-verify stored signatures offline during sync (#6131)

Sync now re-verifies each managed entry's stored Sigstore bundle
against the identity recorded in the lock file — entirely offline, via
the embedded trust root — before an entry can count as current
(RFC THV-0080). A failed re-verification is drift: check mode reports
it (the CI gate covers signatures like it covers content drift), and
apply mode reinstalls from the pinned reference, where install-time
verification enforces the locked identity and heals the stored state.
An OCI entry recording a signer identity without a stored bundle fails
closed; git entries store no bundle by design — their signatures are
re-verified when content is re-resolved.

Adoption back-fills provenance from the stored bundle when one exists;
otherwise adopting is the same trust decision as an unsigned install
and now requires the explicit --allow-unsigned exception (new flag on
sync, threaded through the API), recorded as unsigned in the entry.

Part of #5899.

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

82838 of 118469 relevant lines covered (69.92%)

98.0 hits per line

Source Files on job 30826608202.1
  • Tree
  • List 867
  • Changed 15
  • Source Changed 5
  • Coverage Changed 15
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Build 30826608202
  • 1f50e2b4 on github
  • Prev Job for on main (#30825597926.1)
  • Next Job for on main (#30857095576.1)
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc